EX294 · domain
Implement advanced Ansible automation
This domain covers advanced Ansible automation for EX294: controlling execution flow with serial, vars_prompt, and delegation, plus conditional task evaluation. Questions present realistic playbook scenarios and ask you to diagnose hangs, partial runs, or unexpected task results using core Ansible directives and modules rather than ad hoc workarounds.
Focused practice
Practice Implement advanced Ansible automation questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Implement advanced Ansible automation
You must be able to control play execution with serial, delegate tasks to non-inventory hosts, and make playbooks non-interactive for CI. The single most important thing is knowing how Ansible evaluates task results and host failures so you can diagnose partial runs and hangs.
Using serial and max_fail_percentage to control rolling update batches across inventory hosts
Applying delegate_to and run_once to execute tasks on hosts outside the active play target
Handling vars_prompt non-interactively with extra vars or vars_prompt defaults in CI/CD
Writing failed_when and changed_when conditions to override default task result evaluation
Watch out for
Common Implement advanced Ansible automation exam traps
- ▸Assuming vars_prompt can read from stdin in CI; it blocks because no TTY is attached, so pass variables via -e or defaults instead.
- ▸Thinking serial: 1 stops after one host when the real cause is a failure, unreachable host, or max_fail_percentage threshold aborting the play.
- ▸Using delegate_to without also setting run_once or connection details, causing the task to run once per host or fail on the delegated target.
Question index
All Implement advanced Ansible automation questions (63)
Click any question to see the full explanation, or start a practice session above.
A role contains a handler. The playbook includes the role and also defines a task that notifies the same handler. When the playbook runs, the handler executes only once. Which of the following best explains this behavior?
Medium2An Ansible playbook is designed to run on a group of database servers. The administrator wants to ensure that a task runs only on the primary database server, which is defined in the inventory with a variable 'primary: true'. Which conditional should be used?
Easy3Drag and drop the steps to configure a network bond (bond0) using nmcli in the correct order.
Medium4A playbook uses serial: 2 and sets any_errors_fatal: true. The first batch of 2 hosts both fail. What happens?
Medium5Which two statements about ansible-vault are true? (Select exactly 2.)
Hard6An administrator needs to securely pass a database password to a playbook without exposing it in logs or the command line. Which approach is the most secure?
Hard7Which TWO of the following are advantages of using 'ansible-pull' over 'ansible-playbook'?
Easy8A playbook uses the copy module to deploy a configuration file. The file should be templated with variables, but the engineer mistakenly uses the 'src' parameter with a static file instead of 'content' or a template module. What is the most likely outcome?
Easy9Refer to the exhibit. The playbook fails because the httpd package is not found. Which is the most likely cause?
Hard10A company uses Ansible Vault to encrypt sensitive data in playbooks. They have multiple environments (dev, test, prod) and use a separate vault password file for each environment. The passwords are stored in files named 'vault-pass-dev', 'vault-pass-test', and 'vault-pass-prod'. To run a playbook against the test environment, they use the command 'ansible-playbook site.yml -i test -e @test-vars.yml --vault-id test@vault-pass-test'. This runs successfully from the command line. However, when they define the same vault-id in an Ansible Tower credential and attempt to run the job, the job fails with 'ERROR! Decryption failed (no vault secrets would be found that could decrypt the vault encrypted file)' for a vault-encrypted variable file that was encrypted with a different vault ID (e.g., 'dev'). The team expects that Tower would use the provided vault credential to decrypt all vault-encrypted files. Which change should be made to ensure correct decryption in Tower?
Hard11An administrator wants to run a playbook with a different user for a specific host. Which variable should be set?
Easy12An Ansible playbook includes a role that defines default variables in 'defaults/main.yml' and role variables in 'vars/main.yml'. A playbook sets the same variable in the play's 'vars' section. Which variable value takes precedence?
Medium13An Ansible playbook uses a rolling update strategy with serial: 1. After the first host is updated, the playbook stops and shows 'PLAY RECAP' with only one host. What is the most likely reason?
Hard14A playbook uses the 'block' feature to group tasks and includes a 'rescue' section. If a task inside the block fails, what happens?
Easy15Which three of the following are valid methods to pass variables to an Ansible playbook at runtime? (Choose three.)
Medium16An organization has a set of common tasks used in many playbooks. The tasks are updated frequently. What is the most maintainable way to share them?
Easy17An administrator wants to reuse a set of tasks that configure a firewall across multiple playbooks. Which Ansible feature should be used to achieve this?
Easy18Refer to the exhibit. What is the purpose of the 'failed_when' condition?
Easy19Refer to the exhibit. After the playbook run fails on the 'Verify config' task, what happens to the 'restart service' handler?
Hard20A playbook uses the `ansible.builtin.uri` module to interact with a REST API. The API requires a Bearer token that is stored in an encrypted variable file. The playbook must ensure the token is not exposed in logs. Which approach best meets the requirement?
Medium21An automation engineer wants to run a playbook only on hosts that belong to both the 'webservers' group and the 'production' group. Which inventory grouping method achieves this?
Easy22A developer reports that a role's behavior is not as expected. They set a variable in the playbook's vars section, but the role still uses the value from its vars/main.yml. Which of the following explains this issue?
Easy23An organization uses separate network hops that require different SSH usernames for different inventory groups. Which Ansible configuration approach ensures each group uses the correct SSH user without duplicating playbooks?
Medium24An Ansible playbook uses async and poll to run a long-running task. The task reports 'async task did not complete within the requested time'. Which of the following is the most likely cause?
Medium25Refer to the exhibit. The playbook copies all .conf files from the control node to host1. If the playbook runs again on the same host without any changes, which task status is expected?
Hard26A playbook uses a loop over a list of packages to ensure they are installed. However, the playbook runs slowly because each package is processed individually. Which optimization technique should be used to improve performance?
Medium27An administrator is writing a playbook that must execute a task only when a file exists on the remote host. They use the `stat` module to check the file and register the result. Which conditional expression should be used to run a subsequent task based on the file's existence?
Hard28A playbook uses a variable named `db_port` that must be defined by the user at runtime, but should fall back to 5432 if the user does not provide it. Which approach ensures this behavior without failing the play when the variable is undefined?
Medium29A playbook includes a role that has a task notifying a handler defined within the role. Another task in the play, outside the role, also notifies the same handler by name. After running the playbook, the administrator notices that the handler runs only once. What is the reason for this behavior?
Medium30A playbook must execute a task on a host that is not part of the inventory, such as a temporary cloud instance. The task should run on that host without modifying the inventory file. Which directive should be used?
Easy31An automation engineer is using Ansible to manage a fleet of servers. They need to ensure that certain tasks run only on hosts that match specific criteria. Which two of the following are valid ways to limit task execution based on host facts? (Choose two.)
Hard32Which TWO of the following are correct about Ansible Vault?
Hard33A playbook uses the 'block' and 'rescue' keywords to handle errors. The block contains three tasks. The first task fails. What happens next?
Medium34Which THREE of the following are valid attributes of the ansible.builtin.service module?
Medium35Which two statements about Ansible roles are correct? (Select exactly 2.)
Easy36An Ansible automation team is designing a playbook to manage network devices. They need to ensure that the playbook can handle transient network failures by retrying failed tasks a specific number of times with a delay between retries. Which approach should they use?
Medium37A playbook uses an Ansible collection that includes a custom module. The module's documentation is missing. What is the best way to locate the module's source code?
Hard38An administrator wants to reuse a set of tasks across multiple playbooks. Which Ansible approach is most appropriate?
Easy39Match each Ansible fact variable to its description.
Medium40Refer to the exhibit. An administrator wants to view the decrypted value of 'db_password' without modifying the file. Which command should be used?
Easy41An administrator needs to run a playbook that applies a configuration only to hosts that have a specific fact, `ansible_processor_vcpus`, greater than 4. The playbook should skip hosts that do not meet this condition. Which approach should be used?
Easy42A playbook uses a task with 'delegate_to: localhost' to generate a report file. The task must run only once, even if the play targets multiple hosts. Which keyword should be added to the task to ensure it executes only on the first host?
Hard43Which THREE of the following are valid uses of the 'ansible.builtin.include_role' module?
Hard44An automation engineer must ensure that a task in a playbook runs only once across all hosts in the play, even though the play targets 50 web servers. The task creates a shared DNS record on an external service. Which approach should be used?
Medium45An administrator needs to securely store a database password used across multiple roles in a shared repository. Which approach is recommended?
Easy46Refer to the exhibit. The playbook fails with an error about the package list. What is the issue?
Hard47Which three methods can be used to pass variables to an Ansible playbook? (Select exactly 3.)
Medium48A playbook uses the 'include_tasks' module to dynamically include tasks based on a variable. The playbook runs successfully on some hosts but fails on others with a 'template error' message. What is the most likely cause?
Hard49Which TWO statements about Ansible collections are correct?
Medium50A company has a large infrastructure with over 1000 servers. They run a playbook that configures NTP on all servers. The playbook takes over 30 minutes due to sequential execution. The team wants to reduce execution time. Which approach should they take?
Hard51A team wants to ensure that a sensitive variable, such as a database password, is not printed when ansible-playbook runs with -v (verbose). What is the best method to achieve this?
Easy52Refer to the exhibit. An Ansible playbook contains the following block structure. If the task inside the block fails, which of the following describes the execution order of the rescue and always sections?
Medium53An Ansible playbook that deploys a web application includes a task that uses the `uri` module to call an external API. The task occasionally fails due to API rate limiting. Which combination of keywords should be added to the task to automatically retry up to 5 times with a 30-second delay between attempts, and only fail if all retries are exhausted?
Hard54An administrator needs to run a playbook in check mode to preview changes on managed hosts, but a critical task using the `command` module must always execute regardless of check mode. Which task directive should be applied to that specific task?
Medium55A new technician runs a playbook that uses the yum module to install packages. The playbook fails with 'No package matching' for a custom package. The package is available on a third-party repository. Which step should the technician take?
Medium56A company uses dynamic inventory from a cloud provider. The playbook needs to run tasks only on instances with a specific tag. The ansible_ec2_tags variable is not available. What is the most efficient method to filter hosts?
Hard57A playbook uses 'vars_prompt' to ask for a confirmation before proceeding with destructive changes. However, when the playbook is run from a CI/CD pipeline, it hangs indefinitely. What is the best way to handle this?
Medium58A playbook uses the 'block' and 'rescue' keywords. If a task in the block fails, but the rescue tasks also fail, what happens?
Medium59An Ansible playbook uses a custom filter plugin located in the `filter_plugins/` directory next to the playbook. The filter is not being applied, and the playbook fails with an error that the filter is undefined. What is the most likely reason?
Hard60A playbook uses import_playbook to include other playbooks. The main playbook is run with --check mode. Which statement is true?
Medium61An Ansible playbook contains many tasks. An administrator wants to run only a subset of tasks by passing '--tags ' at the command line. Which of the following must be added to the tasks?
Easy62You are managing a large infrastructure of 500 Linux servers. The servers are divided into groups: 'web', 'app', and 'db'. Each group has specific configuration requirements. You have developed a set of Ansible roles to manage these configurations. Recently, you noticed that when you run the playbook against all servers, the 'web' role is applied to 'app' servers due to a variable misconfiguration. The playbook uses include_role with a variable that determines which role to apply. The variable is defined in group_vars/all.yml as 'server_role: web'. However, each group should have its own role: 'web' for web servers, 'app' for app servers, 'db' for db servers. The playbook includes the role based on '{{ server_role }}'. What is the best course of action to fix this issue without modifying the playbook structure?
Hard63An Ansible playbook runs tasks on a group of web servers. During a rolling update, the playbook should ensure that no more than 2 servers are taken out of service at the same time. Which play keyword should be used?
MediumOther domains
All EX294 exam domains
Frequently asked questions
- What does the Implement advanced Ansible automation domain cover on the EX294 exam?
- You must be able to control play execution with serial, delegate tasks to non-inventory hosts, and make playbooks non-interactive for CI. The single most important thing is knowing how Ansible evaluates task results and host failures so you can diagnose partial runs and hangs.
- How many questions are in this domain?
- This page lists all 63 Implement advanced Ansible automation questions in the EX294 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Implement advanced Ansible automation questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.